NeurIPS 2026 · SaTQuML Workshop

Adaptive-ShotHybrid Quantum
Anomaly Detection

Validation-calibrated measurement allocation for Tactile Internet security. AS-VQC begins at 128 shots and adds measurements only when an anomaly score remains close to a fixed decision threshold.

Research companion: explore the published method and results. This static Space does not run a detector or execute quantum circuits.

Framework Overview

Adaptive-Shot Variational Quantum Circuit (AS-VQC) inference treats quantum measurements as a per-record resource. A trained hybrid scorer is reused without retraining or threshold recalibration.

Adaptive Measurements

Start at 128 shots. Escalate cumulatively to 256, 512, and 1024 only when the current score is inside the stage’s validation-calibrated margin around the decision threshold.

Decision-Level Reliability

Measure both ranking quality and disagreement with the analytic decision at the same threshold. Stable ranking does not necessarily imply stable individual decisions.

Controlled Evaluation

Compare fixed-shot budgets, three adaptive calibration levels, and a budget-shuffled control across random, entity-group-disjoint, and temporal holdouts.

Method and evaluation: paper, Section 3. The “95” in AS-VQC-95 is a validation-error percentile, not a formal 95% test-correctness guarantee.

4,875
CESNET Candidate Records
12
Features / Registered Qubits
15
Trained QNN Checkpoints
1,200
Finite-Shot Policy Realizations

Five checkpoints per holdout. Measurement repetitions are not additional independently trained models. Candidate counts precede training-derived filtering.

Adaptive Evidence, Cached Enforcement

Mirrored telemetry is analyzed off-path. The current Tactile Internet request continues through deterministic cached enforcement while later evidence can inform policy updates.

Off-Path Evidence Plane

Mirrored Aggregate-Flow Telemetry
Training-Derived Feature Preparation
Classical Embedder → Quantum Encoding
12-Qubit VQC · Joint Pauli-Z Readout
128 Cumulative Shots → Classical Head
Outside the Calibrated Threshold Margin?Yes: return evidence · No: acquire more shots
Escalate: 256 → 512 → 1024Reuse accumulated measurements; stop at the cap
Return Anomaly Evidence + Shots Used
Subsequent
Policy Updates

On-Path Enforcement Plane

Client / Tactile Request
Policy Enforcement Point
Cached Deterministic Policy Lookup
Grant · Restrict · Step-Up · Deny
Protected Tactile Internet Service
Stopping rule
|p̂S − τ*| > δS,β

Stop when the finite-shot score’s distance from the fixed threshold exceeds the validation-error margin. Otherwise add only enough shots to reach the next cumulative stage. All remaining records stop at 1024.

Scope: this is the scorer’s architectural role, not a measured full PDP/PEP deployment. Reduced shot counts do not themselves establish haptic-loop latency, physical-device energy savings, or production security.

Architecture and stopping policy: paper, Sections 3.3–3.6.

Measurement Savings & Reliability

Primary policy: AS-VQC-95. Measurement realizations are averaged within each checkpoint, then summarized across five checkpoints per holdout. These are reported paper results, not measurements generated by this Space.

Primary AS-VQC-95 results. AUC and shots show mean plus or minus sample standard deviation; saving uncertainty is in percentage points.
HoldoutROC-AUCMean ± SDAverage ShotsMean ± SD per recordSaving vs. Fixed-1024Mean % ± SD in ppDecision DisagreementMean vs. analytic reference
Random0.9956 ± 0.0014129.2 ± 0.487.39% ± 0.04 pp0.771%
Entity-Group0.9968 ± 0.0017276.9 ± 327.372.96% ± 31.97 pp0.409%
Temporal0.9980 ± 0.0010131.2 ± 2.087.19% ± 0.20 pp0.635%

Source: paper, Table 1 and Section 4. “pp” denotes percentage points. Saving = 100 × (1 − average shots / 1024); independently rounded values may not reproduce exactly. Disagreement is with analytic inference, not verified attack ground truth.

Retain the tradeoff: Fixed-1024 is more decision-stable than AS-VQC-95. The Group variability is real in the reported matrix: seed 46 averages 862.4 shots per record, while the other four Group checkpoints remain near the 128-shot floor. It is not excluded as an outlier.

Compared with Fixed-128

AS-VQC-95 has lower reported decision disagreement in each holdout. Its primary advantage is at the thresholded-decision level rather than an identified ranking gain.

Matched Measurement Budget

Budget-Shuffled-AS95 preserves the realized shot-budget distribution but randomly reassigns budgets to records. AS-VQC-95 has lower disagreement in all three holdouts, testing targeted allocation rather than quantity alone.

More Conservative Calibration

AS-VQC-99 reports lower mean disagreement than Fixed-512 while averaging 162.6, 432.9, and 207.7 shots for Random, Group, and Temporal. AS-VQC-95 remains the primary policy.

View the complete AS-VQC-95 predictive metrics
AS-VQC-95 ranking, false-positive-rate, and calibration metrics.
HoldoutROC-AUCAverage PrecisionFPRECE · 15 bins
Random0.9956 ± 0.00140.9760 ± 0.00500.0299 ± 0.00420.0257 ± 0.0062
Entity-Group0.9968 ± 0.00170.9835 ± 0.00920.0346 ± 0.03120.0174 ± 0.0038
Temporal0.9980 ± 0.00100.9895 ± 0.00600.0252 ± 0.01040.0211 ± 0.0076

Mean ± sample SD across five checkpoints. FPR and expected calibration error (ECE) are fractions, not percentages. Labels are training-quantile statistical pseudo-labels.

Experimental Configuration

Hybrid Scorer

12 → 64 → 12 classical embedder; 12-qubit, two-layer VQC with 72 registered parameters and 22 CNOTs; Pauli-Z readout on qubits 0 and 1; 2 → 32 → 2 classical head. The configured readout has three-wire causal support.

Training & Calibration

20 epochs · batch size 32 · Adam at 2 × 10⁻³ · seeds 42–46. Preprocessing uses training data; validation selects checkpoints, thresholds, and adaptive margins. Test labels do not control stopping.

Inference & Controls

Analytic training followed by ideal joint-multinomial sampling. Four fixed budgets, AS-VQC-90/95/99, and a matched-budget shuffled policy reuse the same checkpoints. No physical hardware noise, queueing, or device timing is evaluated.

Benchmark boundary: the 4,875-record CESNET-TimeSeries24 candidate pool contains aggregate network telemetry, not dedicated haptic traffic. Quantile-derived anomaly labels do not establish verified intrusion detection. Validation-error percentiles are empirical calibrations, not formal test-time correctness guarantees.

Configuration and limitations: paper, Section 3 and Section 6. The linked repository contains the experiment workflow; this Space contains no checkpoints or private/raw telemetry.

Authors

Author order, affiliations, and email addresses follow the linked arXiv version.

Mubassir Serneabat Sudipto

College of Engineering
Iowa State University
Ames, Iowa, USA

msudipto@iastate.edu

Shakil Ahmed

College of Computing
Grand Valley State University
Allendale, Michigan, USA

ahmeshak@gvsu.edu

Ashfaq Khokhar

Carl R. Ice College of Engineering
Kansas State University
Manhattan, Kansas, USA

akhokhar@ksu.edu

Samir M. Iqbal

College of Computing
Grand Valley State University
Allendale, Michigan, USA

iqbalsa@gvsu.edu

Citation

Please cite the associated paper when using AS-VQC, its methodology, or the reported measurement–reliability results.

BibTeX · arXiv:2610.05835
@misc{sudipto2026adaptiveshothybridquantum,
  title         = {Adaptive-Shot Hybrid Quantum Anomaly Detection for Tactile Internet Security: Reliability-Aware Measurement Allocation Under Resource Constraints},
  author        = {Sudipto, Mubassir Serneabat and Ahmed, Shakil and Khokhar, Ashfaq and Iqbal, Samir M.},
  year          = {2026},
  eprint        = {2610.05835},
  archivePrefix = {arXiv},
  primaryClass  = {cs.CR},
  doi           = {10.48550/arXiv.2610.05835},
  url           = {https://arxiv.org/abs/2610.05835},
  note          = {NeurIPS 2026 SaTQuML Workshop; short oral presentation reported in the arXiv comments}
}

Workshop presentation status is reported in the arXiv comments; it is not a NeurIPS main-conference acceptance claim.